Probably a refund is all they’ll be on the hook for.
Sadly, damage done like this is just chalked up to an accident, and swept under the rug.
Probably a refund is all they’ll be on the hook for.
Sadly, damage done like this is just chalked up to an accident, and swept under the rug.
From my point of view, one of the greatest problem for them is that they bypassed customers deployment policies.
Caveat emptor. Falcon and other similar security products often push updates at-will, and they're fully transparent about this if you actually read the contract terms and understand the vendor's approach to operations. I have worked with many clients that elect not to use such tools in certain sensitive environments, specifically to mitigate the risk of being impacted by something like CrowdStrike's 7/19 event.
Do you really want to wait until for the weekly/monthly/quarterly deployment window to deploy a detection update for a 0day, or a new type of malware?
By cashing in this $10 Uber Eats coupon you agree to hold harmless...
- https://news.ycombinator.com/item?id=41058261
- https://techcrunch.com/2024/07/24/crowdstrike-offers-a-10-ap...
We put absolutely no critical thought into whether this was a likely thing, and we completely ignored the many government and media reports that are credibly sourced which state that there are known phishing scams and other threat actors trying to capitalize on this incident.”
I highly doubt this is something that Crowdstrike actually did.
Edit: Amazingly they did, the article has been updated with a statement. Amazingly stupid all around.